09.23.10

Gemini version available ♊︎

Like Teaching Children to ‘Smoke’ Safely to Reduce Risk of Cancer

Posted in Deception, Microsoft, Security, Windows at 6:13 pm by Dr. Roy Schestowitz

No smoking

Summary: “National Cyber Security Awareness Month” is being exploited by a programme that receives the support of Howard Schmidt from Microsoft (now Cyber Security Czar); In it, children aged 11-14 would be taught cyber ‘security’ rather than insecure parts of the systems simply removed

“The estimated cost of unsolicited emails to businesses in 2007 was $100 billion,” wrote lnxwalt earlier today, pointing to this page. The overall cost of Windows botnets that dispatch spam and cause other harm may be measurable on the scale of trillions.

Microsoft is currently alerting customers that ASP.NET is a security problem. We covered this in earlier stages of the problem [1, 2]. It affects a lot of Windows-powered Web sites and last night there was a discussion in IRC about the serious Twitter flaw and whether it affects just Internet Explorer, Windows, and Office users. One newly-published article says:

[T]he worms of yore were so devastating because they could exploit a global monoculture: Microsoft Internet Explorer or Microsoft Word running on Microsoft Windows just about everywhere. This made it far simpler to exploit weaknesses in distant PCs, because the actual architecture was known with a high degree of probability.

With the mouseover mess, we were saved by the wonderfully diverse ecosystem of Twitter clients operating through the Twitter API. This meant that assumptions that were correct for code running on the twitter.com site were not valid elsewhere.

This hammers home once more the importance of avoiding monocultures, and encouraging rich and diverse ecosystems (multicultures?) One of the easiest ways of doing that is to adopt free software alternatives to all the Microsoft warhorses. The open source world being what it is, it is far more varied, not least in terms of versions and applications (critics might even call it fragmented). That makes mass attacks hard, and therefore unlikely, since ne-er-do-wells don’t even bother trying when they can just code for Windows.

Open source is certainly not immune to attacks – for example, I fell victim to the mouseover exploit despite using a completely free software stack (thanks, Twitter.com) – but it reduces the risk overall. That means if you are not using it for business, you are increasing that risk – which would be a pretty irresponsible thing to do, no?

On the client side, having Windows cannot help.

Microsoft’s former employee Howard Schmidt of now the Cyber Security Czar in the United State (after a recent appointment which we mentioned in [1, 2, 3, 4, 5, 6, 7]) and rather than calling out Windows and making platform recommendations, he does the usual thing by endorsing/giving people unnecessary ‘education’ about Windows et al. He can’t take Windows off schools’ agenda where Gates (his former boss) is increasingly taking control, can he? Some PR puppets sent us the following E-mails a short while ago, helping to show how Schmidt and his subordinates try to tackle this problem. Below we put the message, without appending an accompanying press release that we omit.

A free program that brings top cyber security experts into schools to teach kids how to avoid online dangers has received the support of White House Cyber Security Coordinator Howard Schmidt.

The (ISC)2 Safe and Secure Online Program, administered by the world’s largest body of information security professionals, brings experts into schools to teach children ages 11-14 how to protect themselves in a cyber-connected world. Issues addressed include cyber bullying, social networking, online predators, identity theft, online reputation, and more.

Launched in the U.S. in the fall of last year, the program has reached more than 30,000 kids. Just in time for National Cyber Security Awareness Month, the U.S. program now has more than 1,000 cyber expert volunteers signed on to conduct presentations this fall.

Please see full details below. If you would like to know if any schools presentations are taking place near you, or if you would like additional information on the program, please contact me. Thank you.

Juliette Mutzke
Maples Communications, Inc.

Schools should not be used to indoctrinate children with presentations on how to use Microsoft software and other products securely (it is often not possible). It is neither effective nor a decent use of school time/budget.

“[W]hen nobody is using Windows, there will be no botnets”

Professor Eben Moglen, 2010

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

2 Comments

  1. twitter said,

    September 23, 2010 at 8:53 pm

    Gravatar

    Ugh, I did not think the cyber bully was a Microsoft indoctrination course … silly me. I’ll have to coach my kid not to laugh out loud at all the silly things they will talk about.

  2. twitter said,

    September 24, 2010 at 8:07 pm

    Gravatar

    Here is a Windows only flaw that’s also sabotage for Firefox on Windows. I had forgotten about this one:

    Heise describes a new demo showing how Firefox running under Windows XP SP2 can be abused to start applications. For this to work, however, Internet Explorer 7 needs to be installed. This severe security problem promises another round in the ‘who-is-to-blame-war’ between Mozilla and Microsoft. Mozilla currently is leading the race for a patch, as they have one ready in their bugzilla database. ‘The authors of the demo note that there are many further examples of such vulnerabilities via registered URIs. What is so far visible is just “the tip of the iceberg”. They state that registered URIs are tantamount to a remote gateway into your computer. To be on the safe side, users should, in the authors’ opinion, deregister all unnecessary URIs – without, however, elucidating which are superfluous.’

    So, some kind of XP SP2 “patch” “registered” a bunch of executables to be remotely executable via any browser. Firefox, putty and other seeminly secure software is as useful on Windows as a vault door is on a straw hut.

DecorWhat Else is New


  1. Links 29/05/2023: Snap and PipeWire Plans as Vendor Lock-in

    Links for the day



  2. Gemini Links 29/05/2023: GNU/Linux Pains and More

    Links for the day



  3. Links 29/05/2023: Election in Fedora, Unifont 15.0.04

    Links for the day



  4. Gemini Links 29/05/2023: Rosy Crow 1.1.1 and Smolver 1.2.1 Released

    Links for the day



  5. IRC Proceedings: Sunday, May 28, 2023

    IRC logs for Sunday, May 28, 2023



  6. Daniel Stenberg Knows Almost Nothing About Gemini and He's Likely Just Protecting His Turf (HTTP/S)

    The man behind Curl, Daniel Stenberg, criticises Gemini; but it's not clear if he even bothered trying it (except very briefly) or just read some inaccurate, one-sided blurbs about it



  7. Links 29/05/2023: Videos Catchup and Gemini FUD

    Links for the day



  8. Links 28/05/2023: Linux 6.4 RC4 and MX Linux 23 Beta

    Links for the day



  9. Gemini Links 28/05/2023: Itanium Day, GNUnet DHT, and More

    Links for the day



  10. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  11. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  12. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  13. Links 28/05/2023: New Wine and More

    Links for the day



  14. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  15. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  16. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?



  17. With EUIPO in Focus, and Even an EU Kangaroo Tribunal, EPO Corruption (and Cross-Pollination With This EU Agency) Becomes a Major Liability/Risk to the EU

    With the UPC days away (an illegal and unconstitutional kangaroo court system, tied to the European Union in spite of critical deficiencies) it’s curious to see EPO scandals of corruption spilling over to the European Union already



  18. European Patent Office (EPO) Management Not Supported by the EPO's Applicants, So Why Is It Still There?

    This third translation in the batch is an article similar to the prior one, but the text is a bit different (“Patente ohne Wert”)



  19. EPO Applicants Complain That Patent Quality Sank and EPO Management Isn't Listening (Nor Caring)

    SUEPO has just released 3 translations of new articles in German (here is the first of the batch); the following is the second of the three (“Kritik am Europäischen Patentamt – Patente ohne Wert?”)



  20. German Media About Industry Patent Quality Charter (IPQC) and the European Patent Office (EPO)

    SUEPO has just released 3 translations of new articles in German; this is the first of the three (“Industrie kritisiert Europäisches Patentamt”)



  21. Geminispace Continues to Grow Even If (or When) Stéphane Bortzmeyer Stops Measuring Its Growth

    A Gemini crawler called Lupa (Free/libre software) has been used for years by Stéphane Bortzmeyer to study Gemini and report on how the community was evolving, especially from a technical perspective; but his own instance of Lupa has produced no up-to-date results for several weeks



  22. Links 27/05/2023: Goodbyes to Tina Turner

    Links for the day



  23. HMRC: You Can Click and Type to Report Crime, But No Feedback or Reference Number Given

    The crimes of Sirius ‘Open Source’ were reported 7 days ago to HMRC (equivalent to the IRS in the US, more or less); but there has been no visible progress and no tracking reference is given to identify the report



  24. IRC Proceedings: Friday, May 26, 2023

    IRC logs for Friday, May 26, 2023



  25. One Week After Sirius Open Source Was Reported to HM Revenue and Customs (HMRC) for Tax Fraud: No Response, No Action, Nothing...

    One week ago we reported tax abuses of Sirius ‘Open Source’ to HMRC; we still wait for any actual signs that HMRC is doing anything at all about the matter (Sirius has British government clients, so maybe they’d rather not look into that, in which case HMRC might be reported to the Ombudsman for malpractice)



  26. Links 26/05/2023: Weston 12.0 Highlights and US Debt Limit Panic

    Links for the day



  27. Gemini Links 26/05/2023: New People in Gemini

    Links for the day



  28. IRC Proceedings: Thursday, May 25, 2023

    IRC logs for Thursday, May 25, 2023



  29. Links 26/05/2023: Qt 6.5.1 and Subsystems in GNUnet

    Links for the day



  30. Links 25/05/2023: Mesa 23.1.1 and Debian Reunion

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts